Impact
A file’s name can contain arbitrary characters a data‑name attribute, retrieved by JavaScript, and inserted into the page’s innerHTML, enabling the execution of attacker‑supplied code in the context of the gallery page. The flaw allows an attacker to run gallery link, potentially leaking data or performing malicious actions within the user’s browser session.
Affected Systems
Vendor smgdkngt’s open‑source Dobase workspace. All releases before Any user who can upload files to a shared folder and share that folder publicly exposes unauthenticated visitors to the XSS attack. The flaw requires that the attacker be an authenticated workspace member who knows the shared folder name.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. The EPSS score is under 1 %, showing a very vulnerability is not listed in the CISA KEV catalog. Exploitation is straightforward: an authenticated member uploads a file with a malicious name into a shared folder, shares the folder publicly, and share link. Because no authentication is required for the victim, the impact can reach any user who follows the public URL.
OpenCVE Enrichment